获取Teams设备管理API令牌后调用接口遇权限验证错误的问题
我希望通过编程方式管理Microsoft Teams设备,比如运行脚本管理配置文件。此前我通过浏览器开发者工具获取令牌来运行脚本,鉴于无需UI交互即可为Teams PowerShell模块编程获取访问令牌,我认为设备管理也可采用相同方式。
首次尝试时,我按照微软的说明获取令牌,仅将作用域替换为所需的https://devicemgmt.teams.microsoft.com/.default。虽然成功获取令牌,但调用https://admin.devicemgmt.teams.microsoft.com/api/v2的任何操作均返回以下错误:
{"error":"Error in validating the roles of the user with tenantId:
, userId: da354b6a-0862-4710-bc0f-bf27e6ccc8cc:MSAL Get Token Exception :- DeviceManagement.Exceptions.MsalAcquireTokenException"}
随后我尝试为应用注册分配“Teams Devices Administrator”角色,授予application_access权限,并添加TeamWorkDevice.ReadWrite.All MS Graph权限(虽不抱期望,因未请求MS Graph令牌,但仍尝试),但均无效果。我不清楚ID为da354...的用户是什么。
观察浏览器中的操作方式,该作用域的令牌是通过client_id 2ddfbe71-ed12-4123-b99b-d5fc8a062a79(推测为TAC的ID)、grant_type refresh_token并提供刷新令牌来获取的,但通过Teams PowerShell获取令牌时未返回refresh_token。
是否有人解决过此问题?
参考我的POST请求内容:
POST https://login.microsoftonline.com/<my tenant id>/oauth2/v2.0/token HTTP/1.1 client_id=<id_of_my_app_registration>&scope=https%3A%2F%2Fdevicemgmt.teams.microsoft.com%2F.default&client_secret=<secret of my app registration>&grant_type=client_credentials
以下是我获取Teams管理API(scope = 48ac35b8-9aa8-4d74-927d-1f4a14a0b239/.default)和MS Graph令牌的登录代码(可正常工作):
var data = new Dictionary<string, string> { { "client_id", id_of_my_app_registration }, { "scope", "48ac35b8-9aa8-4d74-927d-1f4a14a0b239/.default" },//this is a contstant value { "client_secret", secret_of_my_app_registration }, { "grant_type", "client_credentials" } }; var uri = $"https://login.microsoftonline.com/{config.TenantId}/oauth2/v2.0/token"; using var content = new FormUrlEncodedContent(data); var response = await httpClient.PostAsync(uri, content).ConfigureAwait(false); var contentString = await response.Content.ReadAsStringAsync().ConfigureAwait(false); // now get the token from contentString
当我的id_of_my_app_registration拥有正确权限时,可获取并使用令牌;MS Graph同理(只需将作用域替换为https://graph.microsoft.com/.default)。但对于作用域https://devicemgmt.teams.microsoft.com/.default,虽能获取令牌却无法使用,会出现上述错误。
内容的提问来源于stack exchange,提问作者Stephan Steiner

